CVE-2018-5502
published 2018-03-22CVE-2018-5502: On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.40%
69.5th percentile
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Client SSL profile. There is no control plane exposure.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_advanced_firewall_manager | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_application_security_manager | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_domain_name_system | 13.0.0 – 13.1.0.4 | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_global_traffic_manager | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_gtm | — | — |
| f5 | big-ip_link_controller | — | — |
| f5 | big-ip_link_controller | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_local_traffic_manager | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_ltm | — | — |
| f5 | big-ip_pem | — | — |
| f5 | big-ip_policy_enforcement_manager | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_webaccelerator | — | — |
| f5 | big-ip_webaccelerator | >= 13.0.0 < 13.1.0.4 | 13.1.0.4 |
| f5 | big-ip_websafe | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2018-5502: On F5 BIG-IP versions 13
vendor_f5·2018-03-22·CVSS 7.5
CVE-2018-5502 [HIGH] CWE-295 CVE-2018-5502: On F5 BIG-IP versions 13
CVE-2018-5502: On F5 BIG-IP versions 13
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Client SSL profile. There is no control plane exposure.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator, BIG-IP WebSafe
Affected Versions: 1.0.0; 13.0.0 - 13.1.0.4
F5 Advisory Articles: K43121447
F5 References: https://support.f5.com/csp/article/K43121447
GHSA
GHSA-4m7m-7666-wr24: On F5 BIG-IP versions 13
ghsa_unreviewed·2022-05-14
CVE-2018-5502 [HIGH] CWE-295 GHSA-4m7m-7666-wr24: On F5 BIG-IP versions 13
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Client SSL profile. There is no control plane exposure.
No detection rules found.
No public exploits indexed.
2018-03-22
Published